2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28441 | CRITICAL | 9.8 | 1.2% | Mar 22, 2024 | File Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted... |
| CVE-2024-27956 | CRITICAL | 9.8 | 94.0% | Mar 21, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automat... |
| CVE-2024-29243 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the vpn_client... |
| CVE-2024-29876 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/activitylogreport, 'sortby' param... |
| CVE-2024-29875 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort... |
| CVE-2024-29874 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_nam... |
| CVE-2024-29873 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitna... |
| CVE-2024-29872 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. Th... |
| CVE-2024-29871 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/i... |
| CVE-2024-29870 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business... |
| CVE-2024-29866 | CRITICAL | 9.1 | 0.7% | Mar 21, 2024 | Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Or... |
| CVE-2024-29732 | CRITICAL | 9.8 | 0.5% | Mar 21, 2024 | A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthent... |
| CVE-2024-27438 | CRITICAL | 9.8 | 1.0% | Mar 21, 2024 | Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is n... |
| CVE-2024-1148 | CRITICAL | 9.8 | 0.7% | Mar 21, 2024 | Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files... |
| CVE-2024-1147 | CRITICAL | 9.8 | 0.7% | Mar 21, 2024 | Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files. |
| CVE-2024-2161 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects K... |
| CVE-2024-29864 | CRITICAL | 9.8 | 2.9% | Mar 21, 2024 | Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables. |
| CVE-2024-29859 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file ... |
| CVE-2024-29858 | CRITICAL | 9.8 | 0.4% | Mar 21, 2024 | In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid l... |
| CVE-2024-2054 | CRITICAL | 9.8 | 81.3% | Mar 21, 2024 | The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users... |
| CVE-2024-2014 | CRITICAL | 9.8 | 1.1% | Mar 21, 2024 | A vulnerability classified as critical was found in Panabit Panalog 202103080942. This vulnerability affects unknown cod... |
| CVE-2024-28123 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems. In the W... |
| CVE-2024-27922 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure han... |
| CVE-2024-25239 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL comm... |
| CVE-2024-1202 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now